Chadi

2K posts

Chadi banner
Chadi

Chadi

@sb_chadi

🇲🇦| Web3 & AI Security Eng at @Fidesiumapp | Smart Contract Auditor Security, Tooling & Bug bounty hunting talkative nerd

Wherever Katılım Temmuz 2017
1K Takip Edilen401 Takipçiler
Michael Celia
Michael Celia@mcelia·
@jun_song I have checked back on a lot of your stuff and it has been wrong. I don’t think owning ram is good but just the other week you were saying “you only need 128gb” now it’s 256? You engagement farm way too much.
English
4
0
30
1.2K
Jun Song
Jun Song@jun_song·
If you don’t own 256GB of VRAM or unified RAM right now, You will get into serious trouble soon. check back in 6 months
English
110
18
633
51.7K
Chadi
Chadi@sb_chadi·
@alilakrakbi It’s the Blockchain ecosystem Are you operating from Morocco ? Our cybersecurity landscape is inexistant unfortunately but happy to provide assistance if you need
English
0
0
1
9
Ali Lakrakbi 🇲🇦 🚗🔌
@sb_chadi Not sure what web3 is , but for all the rest i totally agree, i shipped products to prodution with know bugs just to keep moving and providing a better product
English
1
0
1
104
Chadi
Chadi@sb_chadi·
Most Web3 founders I talk to aren’t ignoring security. They’re just stuck in an impossible spot: - They need to ship features to stay competitive - Every security review adds weeks and cost - They know one bad incident can wipe out years of work - Good security people are expensive and hard to find “Just get it audited” feels like expensive theater when the real risks are often elsewhere I’ve stopped assuming founders are being reckless. Most of them are doing the best they can with limited time, budget, and information. The ones who eventually reach out usually say the same thing: "We know we need to do better, we just don’t know what actually moves the needle right now." If this sounds familiar, you’re not alone.
English
1
0
0
112
Chadi
Chadi@sb_chadi·
@alilakrakbi You felt the difference after updating codex ?
English
1
0
0
11
Chadi
Chadi@sb_chadi·
@vxunderground the raise of this kind of bs could dilute the attention of the authorities on "real" cybercrime
English
0
0
5
5.4K
vx-underground
vx-underground@vxunderground·
> get dm > "is this malware?" > look inside > malicious libre office macro > looks funny tho > raw shellcode > 2,0,1,187,192,168,45,246 > malware tries connecting to IP address > 192.168.45.246:443 > malware delivered from a live website these dumb fucks vibe coded a malware payload and had it connect back to a local ip address. are they actually fucking retarded???
English
118
265
11.4K
448.1K
Chadi
Chadi@sb_chadi·
@alilakrakbi These kind of tools are certainly already out there in the darkweb between the hands of the big actors I just hope the defensive side moves on with all the cybersecurity restrictions with the models used
English
0
0
0
13
Ali Lakrakbi 🇲🇦 🚗🔌
🤯🤯🤯🤯the security game is changing, and not sure if we have tools to actively monitor and secure to avoid this type of attacks.
Brian Roemmele@BrianRoemmele

🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency. What happened… An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure. It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters. All over a single weekend. 17,000+ logged actions. Official disclosure: huggingface.co/blog/security-… The part that should make every one stop and think: When HF’s own security team tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them. BLOCKED THEM. The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.” They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API. This is why open source (specifically open-weight + self-hosted) wins in the agentic era. The asymmetry is now structural: • Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down. • Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened. Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore. Self-hosted open-weight models remove that choke point. You control the weights. You control the context window. You decide what restrictions (if any) apply. Your sensitive logs and credentials never leave your perimeter during analysis. You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see. HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place. They also used LLM-driven detection and triage on their own side. But the deeper signal is clear: In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional. The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed. Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter. It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”. The agentic future is not coming. It is already probing production infrastructure. The question is no longer whether you will face autonomous agents. It is whether your analysis and response systems will still work when they arrive. And Dario, you and your game playing, ivory tower company is not needed.

English
2
1
36
5K
Chadi
Chadi@sb_chadi·
I agree with you I believe that the future of cybersecurity is in the infrastructure. Big actors like hugging face should be able to higher qualified security companies to handle their incident response. (It will then be the cybersecurity companies role to be on point) But like we say security is a process not an event, it’s something you have to think about through the whole process. And thats the responsibility of the companies that users trust with their data
English
1
0
0
27
Ali Lakrakbi 🇲🇦 🚗🔌
@sb_chadi Not everyone can afford to self host an opensource model, not sure if they even have the resources to build a counter attack, if someone is spending weeks to build a bad AI, it could be so good that it doesn’t leave traces.
English
1
0
1
58
Chadi retweetledi
IT Guy
IT Guy@T3chFalcon·
Your browser's autofill feature is stealing your data. sorry, not your browser. attackers using your browser against you. You land on a page with a form. looks normal. two visible fields. name and email. you click into the name field and let autofill do its thing. behind the page are six more fields you cannot see. hidden with CSS. pushed off-screen. invisible to you. not to your browser. when autofill populates the visible fields it populates all recognized fields simultaneously. including the hidden ones. your name. email. home address. phone number. credit card number. all of it. submitted silently when you hit send. Nearly 40% of malicious web attacks now involve formjacking, injecting hidden fields into legitimate or fake forms to harvest autofilled data. the attack doesn't require you to click a suspicious link. it doesn't require you to download anything. it doesn't require you to type a single sensitive character. it just needs you to autofill a form on the wrong page.
PhishCore™️@PhishCore

Don't sleep on autofill phishing; It's one of the sneakiest and most underrated attack vectors people encounter daily.

English
19
310
1.2K
51.4K
Chadi retweetledi
alz
alz@alz_zyd_·
it's been a few years now and nobody has vibecoded anything worth anything this shows that code has never been the bottleneck for building anything worth building
English
432
122
4K
502.9K
Chadi
Chadi@sb_chadi·
@Capetlevrai Capet reste sur les optimisations Windows et arrête de raconter des salades bro
Français
0
0
0
96
CAPET ☀️
CAPET ☀️@Capetlevrai·
Si Kimi K3 est aussi puissant qu’Opus 4.8 et GPT 5.5, attendez vous à une pluie de piratages informatiques en crypto dans les jours et semaines à venir. Car celui là il peut tourner en local et on peut retirer toute forme de censure donc tous les prompts malveillants vont passer
Français
29
16
352
89K
Chadi
Chadi@sb_chadi·
@shadcn That’s why it’s important to differentiate between the actual tech and the marketing
English
0
0
0
11
shadcn
shadcn@shadcn·
few weeks ago, Fable 5 was so advanced it needed the gov and had to be taken offline. today, we have access to arguably better models for $20/month. took what? six weeks?
English
373
824
23.3K
859.7K
Chadi
Chadi@sb_chadi·
@netcapgirl Still waiting to see what is acheived with Fable that couldn’t be with another model
English
1
0
0
784
Chadi
Chadi@sb_chadi·
@nol_tech @IceSolst Traditional pentesting and web3 audits share this bullshit from clients but in different ways. We flag stuff that they judge useless. You don't flag useless stuff (for the business context), and they complain.
English
0
0
0
15
nol
nol@nol_tech·
@IceSolst I once delivered a pentest debrief to a client where we had fully compromised their AD from the internet, and the client yelled at us for not flagging "Missing HSTS" on random sites. So pentest firms wouldn't be the first ones I'd blame for this depressing result.
English
2
0
51
1.6K
solst/ICE of Astarte
Just saw a pentest firm report “no DNSSEC” as a finding, and maybe it IS time we replace all pentest firms with ai bots
English
42
15
498
28.6K
Chadi
Chadi@sb_chadi·
@0x15_eth That would be a funny hall of fame
English
0
0
0
177
0x15
0x15@0x15_eth·
I'm tempted to put out a list of the most shitty projects to avoid on immunefi for peace of mind
English
24
0
128
4.7K
Chadi
Chadi@sb_chadi·
@NumeroLmou9ana3 I hate it everytime I be reading “wow X or Y moroccan “startup” just raised and then you see that they deliver food or sell some fkin matcha with vitamins
English
1
0
5
644
Chadi
Chadi@sb_chadi·
@theleviaaron @crptAtlas Plan mode tries to structure what you want it to give you as an output and steps to get there But you don’t have that much control and automation You can’t sum up the whole process of software engineering by just pressing PLAN
English
0
0
0
59
Levi
Levi@theleviaaron·
@crptAtlas Killed the worst part of vibe coding? … plan mode has been around for ages 🤨
English
1
0
1
2.9K
Atlas
Atlas@crptAtlas·
GITHUB JUST KILLED THE WORST PART OF VIBE CODING they shipped a free tool called Spec Kit and it already crossed 120,000 stars the fix is stupidly simple instead of tossing vague prompts at an agent and praying it doesn't wreck your project Spec Kit makes the AI write a full structured spec before it touches a single line of code it works through the problem first figures out what you want to build asks about the gaps lays out the project then it starts coding you get fewer insane bugs, cleaner output and results you can predict the flow looks like this: /constitution for your rules and standards /specify for what you want to build /clarify for the open questions before you start /plan for architecture and stack /tasks for the ordered work /implement to run it it plugs into Claude Code, Cursor, Copilot, Codex, Gemini CLI and 25+ other agents 120,000 stars, 10,000 forks, open source, shipped by GitHub itself learning to drive agents like this is most of what separates people getting hired as AI engineers from everyone still fighting their prompts
Atlas@crptAtlas

x.com/i/article/2074…

English
74
324
2.6K
494.5K